team · reference
Roles and permissions
What each of the four workspace roles can do, and which actions only the owner can take.
A workspace has four roles. Everyone you invite gets exactly one of them, and it decides what they see and what they can change.
The four roles
| Role | Who it is for |
|---|---|
| Owner | The person accountable for the business. Everything, including money and audit. |
| Admin | Runs the workspace day to day — settings, integrations, team — but not billing. |
| Member | Works with customers and the catalog. Does not change how the workspace is set up. |
| Viewer | Reads the dashboard. Changes nothing. |
What each role can do
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View the dashboard | ✅ | ✅ | ✅ | ✅ |
| Reply in conversations | ✅ | ✅ | ✅ | — |
| Assign conversations | ✅ | ✅ | ✅ | — |
| Resolve escalations | ✅ | ✅ | ✅ | — |
| Manage orders | ✅ | ✅ | ✅ | — |
| Manage the catalog | ✅ | ✅ | ✅ | — |
| Manage settings and integrations | ✅ | ✅ | — | — |
| Manage the team | ✅ | ✅ | — | — |
| Manage billing | ✅ | — | — | — |
| View the audit log | ✅ | — | — | — |
| Manage SSO | ✅ | — | — | — |
Why three permissions are owner-only
Billing, the audit log and SSO are held back from admins deliberately, and the reason is the same for all three: each one lets someone change what the business is committed to, or see what everyone else has done, without anyone being able to see them do it.
- Billing commits real money.
- The audit log records who did what — including the owner. Someone able to read it can also learn what is unwatched.
- SSO controls who can enter the workspace at all. Changing it can hand access to people the owner never invited.
An admin who needs one of these asks the owner. That friction is the point.
Changing someone's role
Settings → Team. Only an owner or an admin can change roles, and only an owner can grant the owner role.
Removing someone does not delete their history: the conversations they answered and the orders they touched keep their name, because a record of who did what is the thing an audit log is for.
What roles do NOT control
Roles decide what a person may do. They do not decide what the agent may do — that is set separately in the agent's own settings, and no role grants a customer-facing capability the agent does not already have.